Enterprise knowledge, permission-aware

Everything your organisation knows, in one question. And only what the asker is allowed to see.

Ask Todo answers questions about the work itself — what was decided, why something is stuck, what changed while you were away — with a link to the source behind every claim. It lives inside the system the work already runs in, and enforces the permissions you already set.

Every claim carries a source·No reach beyond your access·Built for Hebrew, not translated
Why is the version 4 launch slipping?

The launch was pushed back over the image-loading bug opened on 12/03, still open1

The call summary from 18/03 agreed to freeze the gallery until it closes2

Sources
1Ticket #4182 · "Images not loading" · Dana · 12/03
2Call summary · 18/03 · 04:12
3File · "Gallery spec v3.pdf" · p. 4
Answered from 3 of the 5 projects in this folder — the ones you have access to
No source, no claimAn uncited sentence isn't written
17leak tests that block a release
The part that has to be right

A knowledge assistant that leaks once is finished.

It is the number-one objection in this category, and rightly so: the moment an assistant hands someone a document they were never meant to see, no apology undoes it. So permissions here are not a feature, they are the structure — and we would rather explain how it works than promise you it's safe.

Permission is evaluated at question time against the source tables — never baked into the index
Removed someone from a project? It takes effect on their next question, not the next indexing run
The index holds no field that takes part in a permission decision — precisely so none can go stale
17 leak tests run before every release. One fails, nothing ships
The rule that decides what may be stored: a field whose staleness narrows the results is allowed. A field whose staleness widens them is not. That is the difference between lower recall and a leak, and we take the first every time.
Same question, three people
DDana · project managerSees the ticket, the call summary and the hourly rate5 sources
YYoav · external supplierSees the ticket he handles. The rest does not exist for him1 source
MMichal · clientSees only what was marked visible to the client2 sources
Sound familiar?

The knowledge exists. It just isn't reachable by anyone who needs it.

The decision is in a comment from eight months ago, the agreement is in a call transcript, and the reasoning is in a file somebody once uploaded. The person who knows where — is on holiday.

"Does anyone remember why we decided this?"Searching tickets for a word that may never have been typedA new hire asking the same question a third timeThe decision is buried in comment 47An hour of scrolling a team conversationThe only person who knew has left
This is what it looks like with Ask Todo
Ask in plain language
The answer arrives with a link to its source
Each person gets an answer within their own access
"What changed while I was away" is a fair question
And the answer turns straight into tasks
How it works

From a plain-language question to an answer you can check

1
Ask where the work is
From inside the ticket, the conversation or the project — the scope is already known, so there is nothing to configure
2
The question is routed
"What's overdue" goes to a structured query; "why is this stuck" goes to semantic search
3
Only what you may see is retrieved
The permission predicate is composed live against the source tables, before anything reaches the model
4
The answer is built with sources
Every claim carries a number linked to the ticket, message, transcript or page in a file
5
And it carries on into the work
A summary, tasks generated from the document, or a note saved to your own private space
All the capabilities

Not chat-with-your-documents — a knowledge layer over the work

The sources are what already happens in your system: tickets and their comments, chat conversations, call transcripts and the files attached to them.

Questions

Ask in plain language

"What was decided about pricing", "why is the launch slipping", "what moved this week" — ordinary phrasing, no search syntax and no keywords.

Sources

A clickable citation per claim

Clicking a source opens the item itself inside Todo — the ticket, the message or the file — not a text panel you cannot verify.

Summaries

"Summarise" without phrasing a question

One button on a long ticket or a conversation. It is the button people actually press, because it doesn't require knowing what to ask.

Structured

Numbers from the data, not the model

"What's overdue", "who owns this", "how much time went in" are answered by querying the data — a model shouldn't guess a number you can count.

Time

"What changed while I was away"

Every item carries its date, dates render in your timezone, and "today" is passed to the model explicitly instead of being guessed.

Creation

From a spec document to a task list

Point at a document or a thread and get proposed tasks with titles and descriptions — for you to approve before any are created.

Personal

A private space only you can reach

Notes and files you put there yourself, spanning projects. Nobody else is ever retrieved into them — not a manager, not an administrator.

Control

An admin who decides what goes in

On and off, which sources get indexed, whole projects excluded, and a coverage report showing what was taken in, what failed and why.

Hebrew

Most search engines simply cannot see half the words in Hebrew

A database's standard full-text search ignores short words — in Hebrew that quietly drops some of the most common ones — and it has no concept of prefixes, so "in-the-project" and "project" are unrelated words to it. In Hebrew that is not a small gap; it is half the questions.

The prefix letters and their chains are recognised and stripped
Final-form letters are normalised to their regular forms
Vowel points and quotation marks are removed before matching
An organisational glossary — your own acronyms and internal shorthand
And lexical search runs alongside semantic. Half of real questions contain an exact identifier — a ticket number, a filename, a client name — and that is exactly where embeddings blur and a lexical engine is precise.
What the engine sees
בפרויקטפרויקטPrefix
ושהתקציבתקציבChain
לקוחות״לקוחותQuotes
דףדף2 chars
Four scopes

One system, four entirely different questions

A scope is not four products but four filters over the same index — and each one only narrows. No scope ever widens what you are allowed to see.

In a project — its tickets, comments, files and conversations
In a folder — the projects in it that you can see, and you're told how many of how many
Across the organisation — spanning projects, within your own permissions
Personal — a private space you fill, and only you are retrieved from
Project scope"What's stuck here, and why"Project
Folder scope"What do these three projects have in common"Folder
Organisation scope"What was ever agreed with this client"Org
Personal scope"What did I note down before the launch"Private
Answer integrity

"I didn't find it" is a valid answer, not a failure

An assistant that invents costs more than one that occasionally admits it has nothing. So the refusal here is a designed, deliberate output rather than an edge case somebody forgot.

No source, no claim. An uncited sentence is not written
When information is missing, it says what it did find and offers to widen
Widening the scope is always your click, never automatic
Retrieved text is treated as data only — instructions hidden inside it are not obeyed
And a project without enough material yet simply says so, rather than producing a weak answer. "I didn't find it" when the truth is "I haven't read it yet" is the fastest way to lose trust.
What was agreed on the reseller discount?
I didn't find anything about a reseller discount in what I have access to on this project.
What I did find
1General price list · ticket #3910 · 04/02
Search everything I can see
From answer to action

Knowledge is only worth something once it moves

This is the difference between enterprise search that finds a document and an assistant that sits inside the work: the answer arrives somewhere you can immediately do something with it.

A spec document becomes a proposed task list — for you to approve
A long ticket or conversation summarises in one click
The empty state suggests questions built from the project's real state
A useful answer saves into your own private space
What it does not do: it does not initiate. Ask Todo answers when asked — it doesn't run in the background, raise alerts or act on its own. A proactive assistant is a different product, deliberately.
From answer to action
3 tasks with no owner — who should take them?What moved in the project this week?2 tasks are past their date — what's blocking them?Summarise what was agreed with the client
A suggestion with no basis in the data simply isn't shown
Control and cost

You decide what goes in — and you see exactly what was spent

The two questions that stall projects like this are "what did it actually read" and "what will this cost me this month". Both are answered on a screen, not in a call with support.

Choose which sources are indexed — tickets, comments, chat, calls, files
Exclude whole projects from the index
A coverage report: what was taken in, what's pending, what failed — with the reason
The allowance is shown in questions, not tokens — broken down by user and by project
The model is deliberately simple: one question is one unit, and that ratio is pinned. If we move to a cheaper model it doesn't change how many questions you bought, and if a Hebrew question costs more to run — that is our problem, not yours.
The credits screen
Left this monthquestions840
Resets onmonthly1 Sep
30-day breakdownclarityby user
Transaction logauditcomplete
Who it's for

Organisations where the answer exists — with somebody else

The more people, projects and history you have, the wider the gap between what the organisation knows and what an employee can find.

Professional services firmsConsultancies, accountants and law firms — every client is a file, and its history is the product.
Agencies and software housesDozens of concurrent projects, each with its own spec, changes and decisions.
Organisations with distributed teamsWhen not everyone shares a room, "what did we agree" stops being a question you can shout.
Teams with turnover or hiringA new hire who can ask the system instead of interrupting a veteran three times a day.
Organisations after a merger or growthWhen knowledge is spread across several ways of working and nobody knows which document is current.
Departments with sensitive accessFinance, legal and HR — where the line between who sees and who doesn't is the whole story.
Businesses working with suppliers and clientsWhen outside parties share the same system and must see only their own part of it.
FAQ

Everything you wanted to know

No, and we would rather say so up front. Ask Todo answers on the work already inside Todo: tickets and their comments, chat conversations, call transcripts and the files attached to them. It is not a broad enterprise search tool indexing every system you own. The practical distinction: broad search is good at discovering scattered information, and an assistant living inside the work system is good at understanding context and carrying on into action. If most of your work runs in Todo, this is exactly its case.

Two ways that reinforce each other. First: permission is computed at question time against the source tables rather than stored ahead of time on the indexed content — so removing someone from a project takes effect on their very next question, with no staleness window. Second: the index stores no field that participates in a permission decision, precisely so none can go stale and widen access by accident. Before every release, 17 tests each try to leak something specific; if one fails, nothing ships.

No. It is the one scope in the system with no back door — not for a manager, not for an administrator, and not through another user's export request. You can see, edit and delete every item in it. Just as importantly, the personal space indexes nothing on its own: only what you explicitly put there goes in.

Really in Hebrew, and it was a separate piece of work. A database's standard lexical search drops short words from the index and cannot recognise prefixes, so the prefixed and unprefixed forms of the same Hebrew word are strangers to each other. We built our own tokenizer that strips prefixes and their chains, normalises final-form letters and removes vowel points and quote marks, and ranks with BM25 — alongside a glossary you define for the acronyms only your organisation understands.

Several things together. Every factual claim must carry a citation, and a sentence without a source simply isn't written. Questions with an exact answer in the data — what's overdue, who owns it, how much time was logged — are answered by querying the data rather than the model, because a number you can count shouldn't be guessed. And when there isn't enough material, the answer is "I didn't find that in what I have access to", together with what was found. The refusal is designed, not a failure.

No, and that is a stated red line rather than an omission. There are no productivity scores, no employee rankings and no "who works slowly". Even in personal memory, a fact of the form "usually runs late" is forbidden — that is monitoring, not memory. The product answers questions about the work; it does not offer opinions about the people.

The model is credits, and the rule is simple: one question is one unit, and that ratio is pinned rather than floating against our costs. The screen shows how many questions remain, when the allowance resets, a 30-day breakdown by user and by project, and a full transaction log — so "where did the credits go" is answered on a screen. Prices and packs are settings that get updated from time to time, so we won't print a number here that goes stale — we'll walk through them together on the demo.

Let's get started

Ask it about your real project, and see what comes back

Leave your details and we'll switch it on for one scope of yours, show how permissions behave across two different users, and answer questions you choose.

1Leave your detailsWe'll get back to you the same day.
2We'll pick one scopeA real project or folder — not a polished demo environment.
3Ask, and see the limits tooIncluding what happens when someone without access asks.
Get a personal demo
Send
No commitment, no credit card.